CVE-2021-25084
Estado: ModificadaMedia (4.3)—
The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.65%
- Percentil entre todas las CVEs puntuadas: 49
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-862
- CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-25084",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:P/A:N",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "Advanced Cron Manager",
"versions": [
{
"status": "affected",
"version": "2.4.2",
"lessThan": "2.4.2",
"versionType": "custom"
}
]
},
{
"vendor": "Unknown",
"product": "Advanced Cron Manager Pro",
"versions": [
{
"status": "affected",
"version": "2.5.3",
"lessThan": "2.5.3",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-02-07T16:15:44.627",
"references": [
{
"url": "https://wpscan.com/vulnerability/7c5c602f-499f-431b-80bc-507053984a06",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/7c5c602f-499f-431b-80bc-507053984a06",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example"
},
{
"lang": "es",
"value": "El plugin Advanced Cron Manager WordPress antes de la versión 2.4.2 y el plugin Advanced Cron Manager Pro WordPress antes de la versión 2.5.3 no tienen comprobaciones de autorización en algunas de sus acciones AJAX, lo que permite que cualquier usuario autentificado, como el suscriptor, las llame y añada o elimine eventos así como horarios, por ejemplo"
}
],
"lastModified": "2026-06-17T03:41:25.960",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:-:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "59565771-1752-4100-969C-E678D96C77F4",
"versionEndExcluding": "2.4.2"
},
{
"criteria": "cpe:2.3:a:bracketspace:advanced_cron_manager:*:*:*:*:pro:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "0244A123-5007-471B-B9DD-2F391E134C5E",
"versionEndExcluding": "2.5.3"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}